Mudi7 Remote Effective date: Sep 17, 2026 Version: 1.5

Mudi7 Remote Privacy Policy

How Mudi7 Remote handles local router data, credentials, encrypted backups, VPN configurations, OpenClash tools, support and website visits.

Back to product
On this page

Summary

Mudi7 Remote is an independent iPhone, iPad and Mac companion for a user’s Mudi 7 router. The app communicates directly with the router over local Wi-Fi. It does not use a developer cloud account, advertising or analytics SDK, and does not upload router credentials or readings to the developer.

This policy covers version 1.5 of Mudi7 Remote and its support pages. Effective September 17, 2026. Version 1.4 is available now on iPhone and iPad. The native macOS edition is being prepared for App Store review and is not yet available publicly. Version 1.5 is an upcoming update subject to App Store review; the network-event and trend retention below applies to 1.5.

macOS edition

The native Mac edition requires macOS 14 or later and uses its own sandbox and device-only Keychain pairing. A login saved on iPhone does not transfer to Mac. Mac files remain in the app sandbox unless you explicitly import or export through the system file picker; your chosen destination may be cloud-backed. Automatic reads pause when the app is inactive, hidden, minimized or the Mac sleeps. This edition has no desktop widget or camera QR scanner; import VPN configurations from a file. References to widgets and camera scanning below apply only to iPhone and iPad.

Communication with your router

The app sends login information to your router over encrypted SSH to authenticate. It then sends the commands and settings you choose and receives router status, configuration and connected-device information. This can include battery level, temperature, network names, local addresses, cellular information and router-reported usage.

This information is exchanged with your own router to provide the features you request. It is not sent to a Mudi7 Remote server; no such server operates the app. Your router can store settings you apply. Its firmware, internet connection and third-party services operate independently under their own settings and policies.

The app’s router connection is restricted to supported local Wi-Fi IPv4 addresses on the current subnet. It does not connect through a developer relay or use cellular data to reach a remote router. Local Wi-Fi and Local Network permission are still required even when the router has no internet connection.

Saved login and preferences

After a successful verified login, the app stores the router address, username, password and paired SSH host identity in this device’s Keychain. The record uses device-only protection and is not synchronized through iCloud Keychain. Future connections check the saved router identity.

Appearance, automatic connection, refresh mode and interval, section expansion, Nodes display order, node favorites and selection presets are stored locally in the app’s preferences. OpenClash favorites and presets are scoped to the paired router and configuration and may include group and node names. The app does not provide a cloud-sync service for them. Operating-system backup behavior is separate from the app’s own synchronization behavior.

Network events (observation gaps and changes in uplink availability, SIM slot, network mode, charging or uptime) are retained locally for up to 30 days or 2,000 records per paired router. Event files are excluded from backup. On iPhone and iPad they use device file protection; on Mac they remain in the app sandbox. They contain no passwords, subscriber IDs, network names, client identities, domains or raw logs. Device → Network Events → Clear deletes them; Forget Router also clears the current router’s events. Trend samples cover up to one hour in session memory; missing intervals are not reconstructed.

Most device readings and recent diagnostic activity are held in memory for the app session. The app also stores the latest widget snapshot (battery, temperature, signal and read time) and one trip usage summary locally on this device. These files are excluded from backup. Widgets have no router login, Wi-Fi names, subscriber identifiers, client identities or SMS and do not connect to the router. The app does not maintain a developer-side history of your router activity. Diagnostics are not automatically sent to support.

When you open SMS or Wi-Fi sharing, the app reads the requested messages or network credentials from your router into memory. They clear when you leave that page or the app becomes inactive. Copy Message uses a device-local clipboard item. On iPhone and iPad it has a one-minute expiration. On Mac the app clears its own unchanged copy after one minute while running or on ordinary app termination; it cannot clear it after a crash or forced termination. Another app you paste into may retain its own copy. Wi-Fi QR codes grant access to that Wi-Fi network to anyone who scans them.

Signal sampling and trip recording start only when you choose Start and stop when you leave the page, lock your device, or disconnect. Trip totals cover observed intervals only and are not carrier billing. The app does not send background status notifications or SMS forwarding.

Foreground refresh and router schedules

Settings → Refresh offers Automatic · While Open or Manual, with automatic intervals of 10, 30, 60 or 120 seconds (30 by default). Automatic reads occur only on supported visible status pages, pause during settings/editing and stop when the app is inactive or in the background. Manual mode retains initial page reads, explicit refresh and verification after a requested change. More frequent requests may use more router battery; no measured battery-life claim is made. Separate live signal, trip and Connections monitors require an explicit start/toggle. Widgets show saved readings, not a live router connection.

Configured restart or supported screen schedules execute on the router, independently of the app. Optional usage history is read from an installed router recorder such as nlbwmon. The app does not install packages, run background router polling or forward SMS.

Configuration backups

When you create a backup, or before supported persistent network, VPN or provider changes, the app saves a router configuration archive on this device. It can contain network identifiers, settings and credentials included by the router. The archive, name and summary are encrypted locally; the encryption key uses device-only Keychain protection. Backup files are excluded from iCloud device backup and are not uploaded to the developer.

Saved backups remain until you delete them or remove the app’s container. Forget Router does not delete these archives. You can inspect their included-file list and delete them in Device → Device Tools → Backup & Restore. They cover the router’s selected configuration files, not the entire router disk or necessarily every OpenClash provider asset.

Router VPN and optional external services

Device → VPN manages WireGuard and OpenVPN client/server functions on the user’s router, including profiles, tunnel policies, fallback order and authorized server devices. Tailscale and ZeroTier are optional router services with external infrastructure and separate account/network approval. The app provides no VPN servers, proxy nodes, subscription, traffic relay or system VPN profile. It has no iOS or macOS packet tunnel; traffic forwarding takes place on the router. The selected network and VPN/overlay providers may process traffic and connection information under their own practices. An enabled setting alone does not establish a working or private route.

VPN configurations and QR scanning

VPN import reads the configuration file you select or, on iPhone and iPad, a WireGuard QR code you choose to scan. QR scanning uses camera permission to recognize the code locally; no photograph is saved or uploaded. Configuration data can include private keys, certificates, endpoints and credentials. Requested imports and settings are sent to your router through the local encrypted connection; router-side profiles remain on your router until you remove them there.

Imported configuration bytes and passwords are held in memory and cleared on leaving the form (except while its file picker or QR scanner is open), or when the app enters the background. Exported configuration previews clear on leaving their view or when the app becomes inactive. Saving a configuration to Files creates a separate copy in your chosen location; that location may be cloud-backed. A recipient you later share it with may retain their own copy. Optional Tailscale or ZeroTier account actions can open the corresponding external service under that service’s privacy practices.

Network settings and usage

Supported Wi-Fi/SIM, client names/access limits, DHCP reservations, DNS, AdGuard Home and schedule changes are sent to the paired router, where the resulting configuration can remain until you change or remove it. AdGuard details require its compatible local API; DNS and VPN interaction checks can disable unsupported combinations. LAN conflict checks are diagnostic and do not automatically renumber your network. Router usage and provider counters are not carrier billing or remaining mobile-data allowance.

OpenClash inspection and explicit network checks

Connections can display source-device addresses, destination domains or IP addresses, routing paths and traffic counters read from the router. Connection snapshots and foreground refresh state are cleared when you leave the view, the app becomes inactive or the router disconnects. This is a view of traffic handled by the core, not a developer-side browsing history. Rules and provider collections are read from the existing router configuration.

Node latency checks run only when requested and cause traffic to Google’s gstatic.com connectivity endpoint through the tested router path. An explicit DNS check sends a query through the router to its configured resolver. Connection Check can resolve example.com and send three ICMP pings to Cloudflare’s 1.1.1.1 after you confirm; these external checks are never run automatically. A requested HTTP provider update downloads from that provider’s configured source. Those external services can receive the request and the network address associated with that path. Local control itself does not require these checks, and they do not send results to the developer.

Offline demo

The optional, visibly labeled Demo uses fictional data held in memory. It does not connect to a router, load or save a router login, or persist its example settings. Exiting Demo discards those settings.

Your choices and deletion

Analytics, advertising and payments

The app does not include an advertising SDK, analytics SDK or cross-app tracking service. The developer does not sell router data or use it for advertising.

Apple processes the paid App Store download, payment details and any diagnostics you choose to share with Apple under Apple’s own privacy practices. The app does not collect your payment card information. There are no subscriptions or in-app purchases in Mudi7 Remote.

Support correspondence

The app’s Feedback address is [email protected]; the website also offers [email protected]. If you email either address, your email service and our support email service process the message for delivery. We receive the sender address, message and any attachments you choose to send. We use that information to respond, troubleshoot and handle related requests, not to build advertising profiles.

Please do not send router passwords, Wi-Fi passwords, SIM secrets, full configurations or unredacted network identifiers. When a screenshot is useful, remove private details first.

The app’s Feedback action opens an editable mail draft with an issue prompt and app/build and operating-system version information. It does not attach router logs, profiles or configurations, and it does not send automatically. You can review the recipient and contents in your mail app before deciding whether to send.

Support correspondence is retained only as needed to handle the request and related follow-up, or to meet applicable legal obligations. You may ask for deletion using the same public support address. Router settings held on your own router must be managed there; the developer cannot remotely delete them.

Visiting this website

The website is separate from the app. It is delivered through Cloudflare, which processes web requests and associated technical information for delivery and security. The site also uses Cloudflare Web Analytics for page-view and performance metrics. Read Cloudflare’s Web Analytics explanation and Cloudflare’s privacy policy.

A light/dark theme preference may be saved in your browser’s local storage. Following external links opens services with their own privacy practices. Website visits and support emails are not part of the app’s local router connection.

Children and security

Mudi7 Remote is a general-purpose router utility and is not directed to children. It does not request age information or create a user account.

Encrypted local communication, host identity checks and device-only credential storage reduce exposure. They do not guarantee absolute security of your phone, Mac, router, firmware or network.

Changes and contact

We will update this policy and its effective date when the described practices change. For support, privacy requests or accessibility feedback, contact [email protected].

Visit setup and support · Back to Mudi7 Remote